Bug #64938 [Com]: libxml_disable_entity_loader setting is shared between threads

From: Date: Mon, 10 Oct 2016 10:27:31 +0000
Subject: Bug #64938 [Com]: libxml_disable_entity_loader setting is shared between threads
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204578@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64938&edit=1

 ID:                 64938
 Comment by:         robert dot egginton at c3media dot co dot uk
 Reported by:        Sjon at hortensius dot net
 Summary:            libxml_disable_entity_loader setting is shared
                     between threads
 Status:             Closed
 Type:               Bug
 Package:            *XML functions
 Operating System:   Archlinux
 PHP Version:        5.4.15
 Assigned To:        remi
 Block user comment: N
 Private report:     N
 CVE-ID:             2015-8866

 New Comment:

I can confirm that I still get the issue with 7.0.11. I run my above checking script and after a few
runs all entries come out as true, so this is still not thread safe.


Previous Comments:
------------------------------------------------------------------------
[2016-07-20 11:39:42] davey@php.net

Automatic comment on behalf of martin@divbyzero.net
Revision: http://git.php.net/?p=php-src.git;a=commit;h=c1eb87ab1a2e2df1868b70cd7b8016c6147092c5
Log: Fix bug #64938: libxml_disable_entity_loader setting is shared between threads

------------------------------------------------------------------------
[2015-12-22 12:35:54] robert dot egginton at c3media dot co dot uk

For mark at netalico dot com:

The workaround for something like Magento (not required for CE>1.9.2.0 when a workaround was
added) is to add this line to the start of your script:

if (function_exists('libxml_disable_entity_loader')) {
    libxml_disable_entity_loader(false);
}

------------------------------------------------------------------------
[2015-12-22 12:26:24] robert dot egginton at c3media dot co dot uk

I'm using 5.5.30 and php-fpm and can reproduce the problem by using the inverse of the script:

Test script:
---------------
<?php

die(var_dump(libxml_disable_entity_loader(true)));

---------------

The default seems to be false for me. After a few hits the results all end up true, so somehow this
value is persisting within php-fpm children.

------------------------------------------------------------------------
[2015-11-25 08:52:53] kaplan@php.net

Also fixed in 5.5.22 (per the commits above).

------------------------------------------------------------------------
[2015-10-16 12:46:00] mark at netalico dot com

Any suggested workarounds for this issue? This bug is pretty critical because it can basically take
down sites running something like Magento. It appears to only be fixed in PHP 5.6, which a lot of
codebases aren't ready for yet.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=64938


--
Edit this bug report at https://bugs.php.net/bug.php?id=64938&edit=1


Thread (16 messages)

« previous php.bugs (#204578) next »